Security Advisory

CVE-2020-28481

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-01-19 14:45:17
Last updated 2024-09-16 20:11:33
Assigner snyk
CVSS score 5.3
State PUBLISHED

Description

The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whitelisted by default.